.\" DO NOT MODIFY THIS FILE! It was generated by help2man 1.49.3. .TH YUBIHSM-SHELL "1" "July 2026" "yubihsm-shell 2.8.0" "User Commands" .SH NAME yubihsm-shell \- manual page for yubihsm-shell 2.8.0 .SH SYNOPSIS .B yubihsm-shell [\fI\,OPTION\/\fR]... .SH DESCRIPTION .TP \fB\-h\fR, \fB\-\-help\fR Print help and exit .TP \fB\-V\fR, \fB\-\-version\fR Print version and exit .TP \fB\-a\fR, \fB\-\-action\fR=\fI\,ENUM\/\fR Action to perform (possible values="benchmark", "blink\-device", "create\-otp\-aead", "decrypt\-aesccm", "decrypt\-aescbc", "decrypt\-aesecb", "decrypt\-oaep", "decrypt\-otp", "decrypt\-pkcs1v15", "delete\-object", "derive\-ecdh", "encrypt\-aesccm", "encrypt\-aescbc", "encrypt\-aesecb", "generate\-asymmetric\-key", "generate\-csr", "generate\-hmac\-key", "generate\-otp\-aead\-key", "generate\-wrap\-key", "generate\-symmetric\-key", "get\-device\-info", "get\-logs", "get\-object\-info", "get\-opaque", "get\-option", "get\-pseudo\-random", "get\-public\-key", "get\-storage\-info", "get\-template", "get\-wrapped", "get\-rsa\-wrapped", "get\-rsa\-wrapped\-key", "get\-device\-pubkey", "list\-objects", "put\-asymmetric\-key", "put\-authentication\-key", "put\-hmac\-key", "put\-opaque", "put\-option", "put\-otp\-aead\-key", "put\-symmetric\-key", "put\-template", "put\-wrap\-key", "put\-rsa\-wrapkey", "put\-public\-wrapkey", "put\-wrapped", "put\-rsa\-wrapped", "put\-rsa\-wrapped\-key", "randomize\-otp\-aead", "reset", "set\-log\-index", "sign\-attestation\-certificate", "sign\-ecdsa", "sign\-eddsa", "sign\-hmac", "sign\-pkcs1v15", "sign\-pss", "sign\-ssh\-certificate") .TP \fB\-p\fR, \fB\-\-password\fR=\fI\,STRING\/\fR Authentication password .TP \fB\-\-authkey\fR=\fI\,SHORT\/\fR Authentication key (default=`1') .TP \fB\-i\fR, \fB\-\-object\-id\fR=\fI\,SHORT\/\fR Object ID (default=`0') .TP \fB\-l\fR, \fB\-\-label\fR=\fI\,STRING\/\fR Object label (default=`') .TP \fB\-d\fR, \fB\-\-domains\fR=\fI\,STRING\/\fR Object domains (default=`1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16') .TP \fB\-c\fR, \fB\-\-capabilities\fR=\fI\,STRING\/\fR Capabilities for an object (default=`0') .TP \fB\-t\fR, \fB\-\-object\-type\fR=\fI\,STRING\/\fR Object type (default=`any') .TP \fB\-y\fR, \fB\-\-ykhsmauth\-label\fR=\fI\,STRING\/\fR Credential label on YubiKey (implicitly enables ykhsmauth) .TP \fB\-r\fR, \fB\-\-ykhsmauth\-reader\fR=\fI\,STRING\/\fR Only use a matching YubiKey reader name (default=`') .TP \fB\-\-delegated\fR=\fI\,STRING\/\fR Delegated capabilities (default=`0') .TP \fB\-\-new\-password\fR=\fI\,STRING\/\fR New authentication password .TP \fB\-A\fR, \fB\-\-algorithm\fR=\fI\,STRING\/\fR Operation algorithm (default=`any') .TP \fB\-\-oaep\fR=\fI\,STRING\/\fR OAEP algorithm. Used primarily with asymmetric wrap (default=`rsa\-oaep\-sha256') .TP \fB\-\-mgf1\fR=\fI\,STRING\/\fR MGF1 algorithm. Used primarily with asymmetric wrap (default=`mgf1\-sha256') .TP \fB\-\-nonce\fR=\fI\,INT\/\fR OTP nonce .TP \fB\-\-iv\fR=\fI\,STRING\/\fR An initialization vector as a hexadecimal string .TP \fB\-\-count\fR=\fI\,INT\/\fR Number of bytes to request (default=`256') .TP \fB\-\-duration\fR=\fI\,INT\/\fR Blink duration in seconds (default=`10') .TP \fB\-\-wrap\-id\fR=\fI\,SHORT\/\fR Wrap key ID .TP \fB\-\-include\-seed\fR Include seed when exporting an ED25519 key under wrap (default=off) .TP \fB\-\-template\-id\fR=\fI\,SHORT\/\fR Template ID .TP \fB\-\-attestation\-id\fR=\fI\,SHORT\/\fR Attestation ID .TP \fB\-\-log\-index\fR=\fI\,INT\/\fR Log index .TP \fB\-\-opt\-name\fR=\fI\,STRING\/\fR Device option name .TP \fB\-\-opt\-value\fR=\fI\,STRING\/\fR Device option value .TP \fB\-\-with\-compression\fR Compress a X509Certificate before importing it into the device or detect compressed certificates when listing objects (default=off) .TP \fB\-S\fR, \fB\-\-subject\fR=\fI\,STRING\/\fR The subject to use for certificate request. The subject must be written as: /CN=host.example.com/OU=test/O=example.com/ .TP \fB\-\-in\fR=\fI\,STRING\/\fR Input data (filename) (default=`\-') .TP \fB\-\-out\fR=\fI\,STRING\/\fR Output data (filename) (default=`\-') .TP \fB\-\-informat\fR=\fI\,ENUM\/\fR Input format (possible values="default", "base64", "binary", "PEM", "password", "hex", "ASCII" default=`default') .TP \fB\-\-outformat\fR=\fI\,ENUM\/\fR Input and output format (possible values="default", "base64", "binary", "PEM", "hex", "ASCII" default=`default') .TP \fB\-f\fR, \fB\-\-config\-file\fR=\fI\,STRING\/\fR Configuration file to read (default=`') .TP \fB\-C\fR, \fB\-\-connector\fR=\fI\,STRING\/\fR List of connectors to use .TP \fB\-\-cacert\fR=\fI\,STRING\/\fR HTTPS cacert for connector .TP \fB\-\-cert\fR=\fI\,STRING\/\fR HTTPS client certificate to authenticate with .TP \fB\-\-key\fR=\fI\,STRING\/\fR HTTPS client certificate key .TP \fB\-\-proxy\fR=\fI\,STRING\/\fR Proxy server to use for connector .TP \fB\-\-noproxy\fR=\fI\,STRING\/\fR Comma separated list of hosts ignore proxy for .TP \fB\-v\fR, \fB\-\-verbose\fR=\fI\,INT\/\fR Print more information (default=`0') .TP \fB\-P\fR, \fB\-\-pre\-connect\fR Connect immediately in interactive mode (default=off) .TP \fB\-\-device\-pubkey\fR=\fI\,STRING\/\fR List of device public keys allowed for asymmetric authentication